admin-graphql
Warn
Audited by Snyk on Aug 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill documents the Shopify Admin GraphQL API and includes explicit mutations that create/complete orders and initiate refunds (e.g., draftOrderComplete, draftOrderCreate/invoiceUrl, refundCreate). These operations can result in money being charged/refunded via the platform — i.e., direct financial execution capabilities within the Shopify payment/order flow.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata